CVE-2022-38038
CVSS 3.1 Score 7.8 of 10 (high)
Details
Summary
CVE-2022-38038 is a Windows Kernel Elevation of Privilege vulnerability (EoP). Attackers can exploit this flaw to gain higher system privileges, potentially leading to unauthorized access and data theft. The vulnerability exists due to an improper access control issue in the Windows Kernel. Successful exploitation requires local access to the affected system, making it a significant threat for organizations with weak security protocols for local access. Microsoft has released a patch to address this vulnerability and strongly advises users to install it as soon as possible to protect their systems.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- Microsoft Windows Server 2008
- Microsoft Windows 7
- Microsoft Windows 10
- Microsoft Windows 8.1
- Microsoft Windows Server 2012
Affected Vendors
- Microsoft